Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
BID:35802
Info
Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 35802 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2922 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2009 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | Qabandi |
| Vulnerable: |
Pixaria Pixaria Gallery 2.3.5 |
| Not Vulnerable: | |
Discussion
Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
Pixaria Gallery is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Pixaria 2.3.5 is vulnerable; other versions may also be affected.
Pixaria Gallery is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Pixaria 2.3.5 is vulnerable; other versions may also be affected.
Exploit / POC
Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
The following exploit code is available:
An attacker can exploit this issue via a browser.
The following exploit code is available:
Solution / Fix
Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
References:
References:
- Pixaria Gallery Homepage (Pixaria)
- Pixaria Security Vulnerability (Patch Released) (Pixaria)